Detect
Syspeace Service follows the Windows Security event log for repeated failed sign-in attempts and other suspicious authentication activity, then evaluates it against configurable rules.
Windows Server exposes sign-in surfaces — Remote Desktop, Exchange, SharePoint, SQL Server, and more — that attackers probe with repeated automated sign-in attempts. Syspeace Service runs on each protected server, watches for that pattern, and blocks the offending addresses. Syspeace Console gives administrators one place to manage every protected server remotely.
Each stage of the Syspeace workflow does one job well, and each is visible to the administrator on its own terms.
Syspeace Service follows the Windows Security event log for repeated failed sign-in attempts and other suspicious authentication activity, then evaluates it against configurable rules.
Syspeace v4 blocks offending IP addresses directly through the Windows Filtering Platform, so enforcement keeps working even when Windows Firewall is disabled or managed by other software.
Syspeace Console connects to every protected server through the Syspeace relay, so administrators can review and configure services remotely without direct line-of-sight to the server.
Access Log and Access Report give administrators a searchable history of sign-in activity, exportable to CSV — plus daily and weekly email reports that summarize what happened without needing to open Console.
Syspeace isn't limited to blocking what it sees locally — it also draws on shared threat intelligence and lets you set your own blocking rules.
Blocks reported across the Syspeace customer community are analyzed for repeat offenders and shared back to every Syspeace installation — so an address flagged on someone else's server can be blocked on yours before it ever attacks it.
Set your own blocking policy beyond Syspeace's defaults — block an entire country outright with Geo IP override lists, or build detection rules with nested and negative conditions (time of day, IP range, sign-in user, and more) in Syspeace v4.


Syspeace Service protects Windows Server, and in Syspeace v4 it's also available for Ubuntu Linux.
See how this applies to a specific environment on the solutions pages.
Not every failed sign-in is treated as an attack. Syspeace evaluates activity against configured rules and thresholds before blocking a source — occasional mistyped sign-ins from a legitimate user are a normal, expected part of that pattern, not an automatic block.
No annual minimum, no rounding up to a fixed plan — choose the servers and dates you need.
Install the full Service and Console package on a trial basis, or compare Syspeace v3 and v4 side by side first.